Careless Whisper: Exploiting Silent Delivery Receipts to Monitor Users on Mobile Instant Messengers
Gabriel K. Gegenhuber, Maximilian G\"unther, Markus Maier, Aljosha Judmayer, Florian Holzbauer, Philipp \'E. Frenzel, Johanna Ullrich

TL;DR
This paper reveals privacy vulnerabilities in mobile instant messaging apps where delivery receipts can be exploited to monitor user activity, extract private information, and launch resource exhaustion attacks without user awareness.
Contribution
It demonstrates a novel exploitation technique using delivery receipts to compromise user privacy and proposes the need for design changes in messaging apps.
Findings
Delivery receipts can be exploited to monitor user activity.
Attackers can infer device status and operating system.
Resource exhaustion attacks are feasible without notifications.
Abstract
With over 3 billion users globally, mobile instant messaging apps have become indispensable for both personal and professional communication. Besides plain messaging, many services implement additional features such as delivery and read receipts informing a user when a message has successfully reached its target. This paper highlights that delivery receipts can pose significant privacy risks to users. We use specifically crafted messages that trigger delivery receipts allowing any user to be pinged without their knowledge or consent. By using this technique at high frequency, we demonstrate how an attacker could extract private information such as the online and activity status of a victim, e.g., screen on/off. Moreover, we can infer the number of currently active user devices and their operating system, as well as launch resource exhaustion attacks, such as draining a user's battery or…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsAdvanced Malware Detection Techniques · User Authentication and Security Systems · Network Security and Intrusion Detection
